Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

231–240 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#231
post #216

Earlier quoted context omitted.

The point of reproducible builds isn't to run an open client, but validate that their copy in the app store matches the source they say it does.

But nobody actually does that.

Not manually, perhaps. But automated integrity checks of reproducible builds are trivial to write.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#232

Earlier quoted context omitted.

Humans follow orders which are given by humans on the basis of data which is analyzed by machines and interpreted by humans. If the machine says "dude is terrorist based on XYZ" and the human cannot realistically verify all of that is factually correct (perhaps the subject's phone was lost as the subject walked by a mosque?), then it is much easier for the human to say "Data says this dude is terrorist" than it is to…

I believe the core problem there is still making extreme decisions without proper evidence. This could happen if the government knows much less about you (e.g. just the info on your driver's license) or much more about you. That is, the problem in these specific examples is not the existence of the data, but rather the willingness to throw caution to the wind and operating on shaky foundations.

Human's have a threshold where their confidence in the accuracy of something will determine their willingness to participate or take action. The machines/algorithms/authority structures and so forth are in place in large part to provide that confidence.

The issue today is that the leadership (in many areas of life from business to military to government), who make the decision to kill/censor/interrupt business/etc or not, are saying "we have to follow the data" without having any understanding of what that really means.

Ultimately, this creates false confidence both in the decision-maker and those that are following their lead. I find it unlikely that there would be anywhere near the same willingness if the 'intelligence' many of these decisions were based on didn't seem as rich and unmistakably correct as it often does.

Of course, the practical effect here is that leadership gets to blame the algorithm/model/data instead of having to accept the blame themselves. If only those pesky engineers and nerds in the lab were better at the job we'd bomb less foreigners.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#233
> Part of the agreement between the US and Denmark was that "the USA does not use the system against Danish citizens and companies. And the other way around". Similar words can be found in an NSA presentation from 2011: "No US collection by Partner and No Host Country collection by US"

At first glance, it sounds OK, but what if the US has similar agreements with some neighboring countries (and as mentioned in the article it has) and uses the data collected via them against Danish citizens and companies and vice versa? Everything will be perfectly legal, but in practice, no one is at safety and the creators of the system who have agreements with many countries have a huge advantage over their so-called "partners" because they are aggregating the big picture, but "the partners" have some guarantees only about the data which is transferred via them and have no guarantees even about it when it leaves their country.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#234
post #141

Earlier quoted context omitted.

Care to enlighten us what some of the "dangers" of metadata are?

https://www.wired.com/story/inside-the-nsas-secret-tool-for-... > Even by that account, the scale of collection brought to mind an evocative phrase from legal scholar Paul Ohm. Any information in sufficient volume, he wrote, amounted to a “database of ruin.” It held personal secrets that “if revealed, would cause more than embarrassment or shame; it would lead to serious, concrete, devastating harm.” Nearly anyone in…

Chekovs gun is a tool for better stories. It does not work in reality, because in the real world it is always a cost to doing things. And extreme action has extreme costs, so very seldom does any country do anything extreme. As an example, nobody has used a nuke in war since ww2.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#235
post #94

Earlier quoted context omitted.

I wish people would emphasize this more. Bitcoin isn't anonymous, and with the legal requirements for reporting transactions, much of what happens on there can be corellated to real-world identities. Far as privacy goes, it's probably a step backwards even from bank accounts and credit cards since there's no warrant needed to access it.

Bitcoin is old and stagnant, the future is full anonymity in the form of zk-snarks, used by millions.

ZCash is barely used, the shielded transactions even less so. Monero is the way forward.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#236
post #82

Earlier quoted context omitted.

This is the first time i hear about WhatsApp storing unecrypted copies of my chats in their cloud. Can you provide more information?

I suppose the AFAIK (I do not use WhatsApp), it's Google backup services on Android. WhatsApp stores the local chat history unencrypted in the device and does not mark it as "do not backup", so the cloud sync service uploads it to the backup service. And Android does not encrypt this information. For contrast, Signal does encrypt the local history and the backups (to the point that is a bit harder to backup the chat…

It's disabled by default. Whatsapp asks you annoyingly to enable it. I have never accepted the cloud back up.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#237

Earlier quoted context omitted.

As an European, does it really make a difference? Is USA really much better than China?

USA has your data already (internet cables), why send it to China? Not going to answer the 2nd question for personal reasons.

I guess as an Italian I don't see China as a bigger threat and probably China is less interested in harvesting my data for the reason that they are not selling me anything by targeting me whenever I do something on the internet?

I speak English, I don't speak Chinese, my continent is watching the US elections tonight, it doesn't happen with Chinese politics, my pears stay awake at night to watch the Oscars, I don't even know if the Chinese equivalent exist, basically what US does is much more relevant in day to day life, what happens in China stays in China, so they are not really trying to buy my attention, which is the most valuable asset I own.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#238

Earlier quoted context omitted.

https://www.wired.com/story/inside-the-nsas-secret-tool-for-... > Even by that account, the scale of collection brought to mind an evocative phrase from legal scholar Paul Ohm. Any information in sufficient volume, he wrote, amounted to a “database of ruin.” It held personal secrets that “if revealed, would cause more than embarrassment or shame; it would lead to serious, concrete, devastating harm.” Nearly anyone in…

Chekovs gun is a tool for better stories. It does not work in reality, because in the real world it is always a cost to doing things. And extreme action has extreme costs, so very seldom does any country do anything extreme. As an example, nobody has used a nuke in war since ww2.

the threat of nukes guides all international political arrangements. what does the digital intelligence and coercion machinery guide?

you may not feel threatened by this arrangement now, but how confident do you feel that these tools will always be controlled by people you trust?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#239
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

It's sometimes useful to say a different thing when explaining to someone that doesn't understand.

For me, the importance of metadata can be conveyed by comparing its usefulness to knowing the answers to the game of 20 Questions.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#240
I take issue with the statement that "Snowden was driven more by fears than by facts". Snowden revealed that the NSA was collecting information about citizens (American and many other countries) indiscriminately, for example every call record, every internet search, every web page viewed, etc. The documents he shared show the NSA's mission to collect ALL data possible, terrorist or not. Additionally it showed that there was basically no oversight when it came to digging into people's private lives; an NSA analyst could type in an email or IP address, click a few buttons, put down a few words for "justification" and then get a live view of someone's internet activity, have access to all of their data held by Microsoft, Google, Apple, Facebook, Skype, etc. This is all bad, and it's real, not just a fear.

BTW the ninth circuit court of appeals ruled that the bulk collection was illegal a couple months ago: https://www.theguardian.com/us-news/2020/sep/03/edward-snowd...

Post reply on HN